Forum Discussion
AnalystGuy
Sep 28, 2020Copper Contributor
What is the Defender ATP equivalent to "gpupdate /force" (force an update of policies on a host)
Hi there, When troubleshooting, how does one tell Windows "Go check with Defender ATP headquarters and update your policy right now?". I'm looking for the equivalent of gpupdate /force to force a...
Thijs Lecomte
Oct 05, 2020Bronze Contributor
For indicators, there isn't anyway to force it AFAIK. It periodically checks for new indicators in the MDATP portal, this shouldn't take long.
How long of a delay are you experiencing?
How long of a delay are you experiencing?
AnalystGuy
Oct 05, 2020Copper Contributor
45 mins to an hour on a couple of tests
- Thijs LecomteOct 05, 2020Bronze ContributorI think is the expected time for things like this. Know that it's a worldwide cloud service, so delays are to be expected.
You could try to create a case for this but I wouldn't get my hopes up.- jcescutJul 19, 2021Brass ContributorSorry for raising this thread.
Most likely this holds true also when enabling Tamper Protection on MDE tenant? It could take up to a couple of hours before the onboarded endpoints switch into a protected mode, right?